A curated dispatch from GajShield

The GajShield Gazette

Lead story

Carhartt data breach exposes information of 12.9 million accounts

The Carhartt data breach is significant not only because approximately 12.9 million customer accounts appear to have been exposed, but because it illustrates several important changes in the way modern data-extortion attacks are being conducted and subsequently reported. The S…

Also today
In brief

Boston Scientific says cyberattack disrupted operations globally

The cyberattack affecting Boston Scientific is a particularly important reminder that cybersecurity incidents in the healthcare technology …

Aug 27, 2026

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The latest findings around Nimbus Manticore are significant because they show how mature threat actors continue to evolve beyond simply dev…

Aug 27, 2026

New GPUThor attack defeats NVIDIA ECC protection for root access

GPUThor is an important development because it challenges a security assumption that has become increasingly important in AI, cloud computi…

Aug 27, 2026

Critical Avada WordPress theme flaw enables zero-click RCE

The discovery of CVE-2026-18431 in the widely used Avada WordPress theme and Fusion Builder plugin is a strong example of why modern applic…

Aug 27, 2026

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The disclosure of CVE-2026-19912 and CVE-2026-19913 in Kaltura mwEmbed is particularly concerning because it demonstrates how a seemingly n…

Aug 26, 2026

Microsoft tests new privacy controls for Windows 11 desktop apps

Microsoft’s decision to test more granular privacy controls for Windows 11 desktop applications is a significant security improvement becau…

Aug 26, 2026

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

The fake Apple Support campaign built around AnonyMousKIT is particularly important because it combines physical device theft, phishing, re…

Aug 26, 2026

Bendix EC80 Brake ECU

The CISA advisory ICSA-26-237-05 is unusually significant because it concerns vulnerabilities in the Bendix EC80 Brake Electronic Control U…

Aug 26, 2026

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) data breach is a strong reminder that organisations do not need to operate banks, hospitals or…

Aug 26, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

The CVE added by CISA on August 25, 2026 is CVE-2026-60004, a critical remote code execution vulnerability in Gitea. CISA’s addition of the…

Aug 26, 2026

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Marimo vulnerability tracked as CVE-2026-75149 is particularly interesting because it turns a notebook file itself into an execution tr…

Aug 25, 2026